Courseiva
Implement and Manage Virtual NetworkinghardMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Virtual Networking Practice Question

Traffic from Subnet-App to the internet is being routed through a virtual appliance unexpectedly. You need to identify which route is being applied to the network interface of VM-App01. Which Azure feature should you use?

⚠ Common exam trap

Watch out — candidates often confuse NSG flow logs (which show traffic filtering) with effective routes (which show routing decisions), leading them to pick NSG flow logs when the question is about path selection rather than security rule evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Effective routes for the network interface

Effective routes for the network interface (NIC) shows the actual routes applied to a specific VM's NIC after evaluating all route tables, virtual network gateway routes, and BGP routes. Since traffic from Subnet-App to the internet is unexpectedly going through a virtual appliance, you need to see which route (e.g., a user-defined route with next hop type VirtualAppliance or VirtualNetworkGateway) is being selected based on the longest prefix match. This tool directly displays the effective next hop for each destination prefix, allowing you to identify the misconfigured route causing the traffic to be redirected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Effective routes for the network interface

    Why this is correct

    Effective routes for a network interface are the authoritative, data-plane view of the actual routing decisions applied to a VM's NIC. They combine Azure system routes, user-defined routes, and BGP routes, and display the selected next hop for each address prefix. To confirm that traffic from the app subnet to the internet uses a specific next hop (e.g., Internet, VPN gateway, or NVA), this blade shows the computed route that is actually used, not just a configured route table.

  • NSG flow logs

    Why it's wrong here

    NSG flow logs capture the outcomes of IP traffic through a network security group, logging whether each flow was allowed or denied based on the security rules. They do not contain any routing information, such as the next hop or the effective route prefix, because routing is evaluated before NSG rules in the Azure network stack. Therefore, NSG flow logs can show that internet traffic is succeeding or being blocked, but they cannot reveal whether that traffic is being sent through a particular route or gateway.

    When this WOULD be correct

    When you need to analyze network traffic patterns, detect anomalies, or troubleshoot connectivity issues related to NSG rules, such as identifying denied or allowed traffic between VMs.

  • Azure Policy compliance

    Why it's wrong here

    Azure Policy compliance evaluates whether Azure resources meet governance rules, such as requiring a specific route table on a subnet or prohibiting certain NSG rules. It is a control-plane auditing mechanism that reports policy evaluation results, not a diagnostic tool that reveals data-plane routing behavior. Even a policy that detects a missing UDR would not show the effective route entries actually applied to a network interface, so it cannot answer where traffic is currently being routed.

    When this WOULD be correct

    An exam question asks: 'You need to ensure that all network interfaces in a subscription have a specific tag. Which Azure feature should you use to audit compliance?' In that case, Azure Policy compliance would be correct.

  • The subscription activity log

    Why it's wrong here

    The subscription activity log records only control-plane events, including create, update, and delete operations on Azure resources like route tables, subnets, and virtual networks. It does not capture data-plane traffic flows or the runtime route entries that are derived for a specific NIC. While associating a route table might appear as an activity log entry, subsequent effective routing behavior—such as the actual next hop for internet-bound traffic—is not contained in this log.

    When this WOULD be correct

    You need to investigate who deleted a critical virtual network or changed a route table in your subscription. The subscription activity log would show the user, timestamp, and details of the management operation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Effective routes for the network interfaceCorrect answer

Why this is correct

Effective routes for a network interface are the authoritative, data-plane view of the actual routing decisions applied to a VM's NIC. They combine Azure system routes, user-defined routes, and BGP routes, and display the selected next hop for each address prefix. To confirm that traffic from the app subnet to the internet uses a specific next hop (e.g., Internet, VPN gateway, or NVA), this blade shows the computed route that is actually used, not just a configured route table.

NSG flow logsWrong answer — click to see why

Why this is wrong here

NSG flow logs record traffic that passes through a network security group, but they do not show the effective route applied to a network interface. The question asks for the route being applied, not the traffic logs.

★ When this WOULD be the correct answer

When you need to analyze network traffic patterns, detect anomalies, or troubleshoot connectivity issues related to NSG rules, such as identifying denied or allowed traffic between VMs.

Why candidates choose this

Candidates may confuse NSG flow logs with route analysis because both involve network troubleshooting, but flow logs focus on traffic flows through NSGs, not routing decisions.

Azure Policy complianceWrong answer — click to see why

Why this is wrong here

Azure Policy compliance checks resource configurations against policies, but it does not show the actual applied routes for a network interface. The question asks for identifying which route is being applied, which requires effective routes, not policy compliance.

★ When this WOULD be the correct answer

An exam question asks: 'You need to ensure that all network interfaces in a subscription have a specific tag. Which Azure feature should you use to audit compliance?' In that case, Azure Policy compliance would be correct.

Why candidates choose this

Candidates may confuse Azure Policy with network troubleshooting tools, thinking policy can enforce or reveal routing behavior, when it only governs resource configurations.

The subscription activity logWrong answer — click to see why

Why this is wrong here

The subscription activity log tracks management-plane operations (e.g., creating or deleting resources), not data-plane routing decisions. It cannot show which route is applied to a specific network interface.

★ When this WOULD be the correct answer

You need to investigate who deleted a critical virtual network or changed a route table in your subscription. The subscription activity log would show the user, timestamp, and details of the management operation.

Why candidates choose this

Candidates may think the activity log records all network events, including routing, because it is a central auditing tool. They overlook that it only captures control-plane actions, not data-plane traffic paths.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.